CVE-2025-43929: High severity kitty kitty vulnerability
openactions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43929?
CVE-2025-43929 is classified as a high severity vulnerability due to the risk of executing potentially harmful local files without user consent.
How do I fix CVE-2025-43929?
To fix CVE-2025-43929, update to version 0.41.0 or later of the Kitty software, which implements user confirmation for executing local files.
What systems are affected by CVE-2025-43929?
CVE-2025-43929 affects versions of Kitty prior to 0.41.0, particularly when linked documents come from untrusted sources.
What type of vulnerability is CVE-2025-43929?
CVE-2025-43929 is a local executable execution vulnerability that allows unintended execution of files through external documents.
Who is impacted by CVE-2025-43929?
Users of Kitty prior to version 0.41.0, especially those using it in conjunction with untrusted documents from applications like KDE Ghostwriter, are impacted by CVE-2025-43929.